schpin.

Security policy

Built to protect
every journey.

This policy explains Schpin’s security approach, the responsibilities shared with users and how researchers can report a suspected vulnerability safely.

LAST UPDATED · 15 August 2026

01

Our security approach

Schpin applies proportionate technical and organisational safeguards to protect accounts, precise journey data, vehicles, community content and service infrastructure. Our approach includes encrypted network transport, environment separation, access controls, protected credential storage, dependency review, input validation, ownership checks and operational monitoring.

No internet-connected service can guarantee absolute security. We assess safeguards according to the sensitivity of the information, foreseeable threats, available technology and the nature and scale of Schpin’s service.

02

Protecting your account and device

Keep iOS updated, use a strong device passcode and Face ID where available, protect access to your email and never share verification codes or credentials. Install Schpin only through an official distribution channel.

Contact us promptly if you suspect unauthorised access. Schpin support will never ask you to disclose a password, one-time code, private key or full access token by email.

03

Location and privacy

Precise routes can reveal homes, workplaces and routines. Review visibility and endpoint privacy settings before sharing, remove unnecessary identifying details and grant location access only on devices you control.

Security controls reduce risk but cannot prevent a permitted viewer from taking a screenshot or sharing information outside Schpin. More information is available in the Privacy Policy.

04

How to report a vulnerability

Email support@schpin.app with a clear description, the affected URL or app version, steps to reproduce, observed impact and any minimal supporting evidence. Use the subject “Security report”. Do not include credentials, unnecessary personal data or precise route history.

We will acknowledge a credible report as soon as reasonably practicable, assess its severity and keep the reporter informed when appropriate. Response and remediation times depend on impact, complexity, third-party involvement and the need to protect users.

05

Safe research boundaries

Research must use accounts, devices and data you own or have explicit permission to test. Stop immediately if you encounter another person’s information, authentication material or a risk of service disruption, and report what occurred without retaining or sharing the data.

Do not use denial-of-service testing, automated high-volume scanning, social engineering, phishing, malware, credential stuffing, physical attacks, spam, extortion, data destruction or tests against employees, users, suppliers or unrelated third-party services.

06

No implied authorisation

This policy is a reporting channel, not blanket permission to access systems or data. Testing that breaches law, privacy, contractual restrictions or the boundaries above is not authorised. If a test could affect real users or production availability, ask for written permission before proceeding.

We do not currently promise a bounty or payment. We may recognise helpful reports at our discretion, but only after obtaining the reporter’s permission.

07

Supported reports

Useful reports may include authentication or authorisation failures, exposure of sensitive information, cross-account access, injection, remote code execution, material request forgery, insecure direct object references or a reproducible weakness in Schpin-controlled infrastructure.

Reports about missing best-practice headers without demonstrated impact, self-XSS, theoretical issues, obsolete app versions, rate limits without a practical security consequence, or vulnerabilities solely in an unrelated provider may be closed as informational.

08

Third-party services

Schpin relies on operating-system, identity, hosting, database, mapping, notification and analytics providers. Report issues in Schpin’s configuration or integration to us. Vulnerabilities solely within another provider should be submitted through that provider’s disclosure process.

Do not test a third party through Schpin in a way that violates its terms or policies.

09

Incident response

When we identify a credible incident, we work to contain it, preserve appropriate evidence, assess affected information, remediate the cause and restore safe operation. We notify affected people and competent authorities when required by applicable law.

Operational details may be withheld where disclosure would create further risk, compromise an investigation or expose confidential information.

10

Policy changes and contact

We may update this policy as Schpin, its infrastructure, threats or legal obligations change. The revised date will appear above. Material changes to reporting expectations will be published on this page.

Security reports and questions should be sent to support@schpin.app. General product support should use the Support page.

Get Schpin for iPhone